Back to skill

Security audit

Multi Agent Config Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill's multi-agent purpose is coherent, but unsafe configuration parsing and unvalidated path-based writes require review before installation.

Install only if you are comfortable granting this skill control over OpenClaw workspace files and subagent orchestration. Before use, the publisher should remove the eval fallback, validate path-derived identifiers, and replace destructive rm -rf documentation with backup or dry-run workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
lib/modelSelector.js:154
Finding

Arbitrary JavaScript Execution Through Unsafe Configuration Parsing

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/archiver.js:44
Finding

Arbitrary Filesystem Writes Through Path Traversal in Workflow and Agent Identifiers

Content
View full analysis
{ if (!params.name) return "❌ Missing --name parameter"; const config = loadJSON(PROFILES_FILE, { agents: [] }); if (config.agents.find(a => a.name === params.name)) { return `❌ Agent "${params.name}" already exists`; } const agent = { name: params.name, description: params.description || "", capabilities: Array.isArray(params.capabilities) ? params.capabilities : (params.capabilities || "").split(",").map(s => s.trim()).filter(Boolean), output_format: params.output_format || "markdown", protocol: params.protocol || "HTTP", tools: Array.isArray(params.tools) ? params.tools : (params.tools || "").split(",").map(s => s.trim()).filter(Boolean), created_at: new Date().toISOString(), updated_at: new Date().toISOString() }; config.agents.push(agent); saveJSON(PROFILES_FILE, config); return `✅ Created agent configuration: ${agent.name}`; }, ``` The persisted name is then used directly in a filesystem path: ```javascript for (const agent of agents) { const agentWorkspace = path.join(CONFIG_DIR, 'agents', agent.name); if (fs.existsSync(agentWorkspace)) { existed.push(agent.name); } else { fs.mkdirSync(agentWorkspace, { recursive: true }); created.push(agent.name); } } ``` Workflow IDs are al ...[truncated 3919 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (143)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The specific command rm -rf ~/.openclaw/workspace/agents is an unsafe deletion primitive in documentation because it encourages irreversible removal of agent data. In the context of a multi-agent orchestration skill, that directory is likely to contain working state or outputs, so the operational risk is higher than a generic example command.

Content

Scanner excerpt · AUDIT_v7.2.0.md (reported line 176)May include surrounding context.

测试步骤:

bash
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The specific command rm -rf ~/.openclaw/workspace/agents is an unsafe deletion primitive in documentation because it encourages irreversible removal of agent data. In the context of a multi-agent orchestration skill, that directory is likely to contain working state or outputs, so the operational risk is higher than a generic example command.

Content

Scanner excerpt · AUDIT_v7.2.0.md (reported line 176)May include surrounding context.

测试步骤:

bash
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The specific command rm -rf ~/.openclaw/workspace/shared can permanently delete shared project artifacts and coordination data. Since this skill manages multi-agent collaboration, deletion of shared state can affect multiple tasks and lead to broader operational disruption than a single-user cache clear.

Content

Scanner excerpt · AUDIT_v7.2.0.md (reported line 177)May include surrounding context.

bash
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 2. 运行检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The specific command rm -rf ~/.openclaw/workspace/shared can permanently delete shared project artifacts and coordination data. Since this skill manages multi-agent collaboration, deletion of shared state can affect multiple tasks and lead to broader operational disruption than a single-user cache clear.

Content

Scanner excerpt · AUDIT_v7.2.0.md (reported line 177)May include surrounding context.

bash
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 2. 运行检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Deleting the profile/configuration file removes local settings and can break or reset agent behavior unexpectedly. While less destructive than recursive directory deletion, it still causes loss of configuration and may be copied verbatim by users following the test procedure.

Content

Scanner excerpt · AUDIT_v7.2.0.md (reported line 178)May include surrounding context.

md
# 1. 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 2. 运行检查
多代理 check_env

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The document explicitly instructs deletion of ~/.openclaw/workspace/agents using rm -rf. In the context of a multi-agent orchestration skill, that directory likely contains agent state, artifacts, or user work product, so copying the command can cause immediate data loss and disruption.

Content

Scanner excerpt · FIX_v7.2.0.md (reported line 202)May include surrounding context.

bash
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The document explicitly instructs deletion of ~/.openclaw/workspace/agents using rm -rf. In the context of a multi-agent orchestration skill, that directory likely contains agent state, artifacts, or user work product, so copying the command can cause immediate data loss and disruption.

Content

Scanner excerpt · FIX_v7.2.0.md (reported line 202)May include surrounding context.

bash
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The rm -rf ~/.openclaw/workspace/shared command recursively deletes the shared workspace, which may contain common data used across agents and projects. Because this skill is designed for project collaboration and workflow orchestration, the context makes deletion more dangerous by increasing the likelihood of collateral loss affecting multiple tasks or users.

Content

Scanner excerpt · FIX_v7.2.0.md (reported line 203)May include surrounding context.

bash
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 运行检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The rm -rf ~/.openclaw/workspace/shared command recursively deletes the shared workspace, which may contain common data used across agents and projects. Because this skill is designed for project collaboration and workflow orchestration, the context makes deletion more dangerous by increasing the likelihood of collateral loss affecting multiple tasks or users.

Content

Scanner excerpt · FIX_v7.2.0.md (reported line 203)May include surrounding context.

bash
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 运行检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

Deleting ~/.openclaw/workspace/.multi-agent-profiles.json can remove configuration or profile state needed for the orchestrator to function correctly. Although narrower than recursive directory deletion, it can still break the environment and cause loss of user-specific setup, especially if executed on a real workspace instead of a throwaway test instance.

Content

Scanner excerpt · FIX_v7.2.0.md (reported line 204)May include surrounding context.

md
# 模拟新电脑环境
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 运行检查
多代理 check_env

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The specific command rm -rf ~/.openclaw/workspace/agents deletes the agents workspace recursively and without confirmation. This is dangerous because it can irreversibly remove agent definitions, generated artifacts, or local state, and users may not understand the blast radius from a brief test snippet.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 145)May include surrounding context.

bash
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The specific command rm -rf ~/.openclaw/workspace/agents deletes the agents workspace recursively and without confirmation. This is dangerous because it can irreversibly remove agent definitions, generated artifacts, or local state, and users may not understand the blast radius from a brief test snippet.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 145)May include surrounding context.

bash
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The command rm -rf ~/.openclaw/workspace/shared deletes the shared workspace recursively and forcefully. In a multi-agent collaboration system, shared directories are especially sensitive because they may contain outputs from multiple workflows, making the damage broader than a single-user cache reset.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 146)May include surrounding context.

bash
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 运行检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The command rm -rf ~/.openclaw/workspace/shared deletes the shared workspace recursively and forcefully. In a multi-agent collaboration system, shared directories are especially sensitive because they may contain outputs from multiple workflows, making the damage broader than a single-user cache reset.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 146)May include surrounding context.

bash
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 运行检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The command removes the multi-agent profiles file, which can erase configuration needed to restore agent behavior or access prior state. Although less severe than directory-wide deletion, it is still destructive and undocumented as such in the surrounding text.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 147)May include surrounding context.

md
# 删除配置
rm -rf ~/.openclaw/workspace/agents
rm -rf ~/.openclaw/workspace/shared
rm ~/.openclaw/workspace/.multi-agent-profiles.json

# 运行检查
多代理 check_env

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The command rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager performs forced recursive removal of the installed skill directory. This can cause accidental loss of local modifications or related artifacts, and in automation-heavy environments destructive install instructions may be executed without sufficient review.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 217)May include surrounding context.

手动升级:

bash
# 1. 删除旧版本
rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager

# 2. 重新安装
clawhub install multi-agent-engine

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The command rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager performs forced recursive removal of the installed skill directory. This can cause accidental loss of local modifications or related artifacts, and in automation-heavy environments destructive install instructions may be executed without sufficient review.

Content

Scanner excerpt · RELEASE_v7.2.0.md (reported line 217)May include surrounding context.

手动升级:

bash
# 1. 删除旧版本
rm -rf ~/.openclaw/workspace/skills/multi-agent-config-manager

# 2. 重新安装
clawhub install multi-agent-engine

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This variant highlights local file validation and reading of multiple files from skill/config directories without clear disclosure. Hidden inspection of local files is relevant in a security review because even read-only access can reveal sensitive metadata or create a larger-than-expected trust boundary.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command, suspicious.dynamic_code_execution

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test_hound_engine.mjs:114

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
AUDIT_v7.2.0.md:176

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
FIX_v7.2.0.md:202

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
RELEASE_v7.2.0.md:145

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
lib/modelSelector.js:172